[2026 Latest] Preventing Residual Permissions with JML Automation: Mastering IDaaS Provisioning

With the average number of SaaS applications per company exceeding 30, account management associated with "JML (Joiner, Mover, Leaver)" is exhausting IT departments. In particular, failing to delete the IDs of former employees is a serious issue directly linked to the risk of information leakage. In our consulting work, we have seen many cases where "ghost accounts" resulting from manual operations are left unattended, serving as entry points for unauthorized access. This article explains specific measures for "IT Department DX"—balancing security and operational efficiency by automating JML processes using the provisioning features of IDaaS (such as Okta and Microsoft Entra ID)—based on our consulting insights.

A professional photograph of a high-resolution computer monitor displaying a sophisticated IT administration dashboard. The screen shows a clean interface with several user profile icons, status indicators like 'Active' and 'Deactivated', and a progress bar for automated synchronization. In the background, a modern, well-lit Japanese office environment is visible with sleek desks and glass partitions, but no people are present, focusing the viewer's attention on the data visualization and the efficiency of the software.

1. The Catastrophic Risks of Failing to Deactivate Former Employee IDs

In IT department support settings, we frequently encounter "ghost accounts" that remain able to log into specific SaaS platforms even months after an employee's departure. This is not merely a management oversight; it is a sign that manual operations have reached their physical limits.

Based on our actual support experience, since individual employees utilize a wide variety of tools, the rate of missed account deletions upon resignation tends to rise sharply once the number of tools exceeds ten. If these are privileged IDs (administrator accounts), it could easily lead to the unauthorized removal of confidential data or configuration changes, potentially undermining the very foundation of corporate trust.

2. How Automated Provisioning via SCIM Integration Works

The core of automation utilizing IDaaS (Identity as a Service) lies in the standard protocol known as SCIM (System for Cross-domain Identity Management). This allows user additions, changes, and deletions on the IDaaS side to be synchronized to each SaaS in real time.

Figure: Rate of missed account deletions by operational model (Estimates based on our consulting track record)

For example, the moment a "resignation" status is finalized in the Human Resources Information System (HRIS), the IDaaS detects it and automatically de-provisions all integrated SaaS accounts in bulk. Common operational errors—such as "suspending an email account but forgetting Slack or core business systems"—can be fundamentally eliminated by implementing SCIM integration.

A professional photograph of a clean, futuristic server room in a Japanese data center. Rows of sleek black server racks are lined up with neatly organized blue and white LED status lights glowing in the dim, cool-toned ambient light. The floor is polished and reflective, creating a sense of high-end technology and security. No people are present, emphasizing the automated and reliable nature of modern IT infrastructure.

Furthermore, in the context of In-house EC site development and growth support, where there is frequent turnover of external partners and temporary staff, this ID provisioning mechanism contributes significantly to reducing operational costs and maintaining information governance.

3. Design Guidelines for Successful Real-World ID Lifecycle Management

When implementing automation, simply introducing tools is not enough. In our actual support engagements, we design "Lifecycle Management" with a focus on the following three points.

A high-angle photograph of a Japanese business meeting room. On a large white table, there is a laptop showing a complex workflow diagram, several tablets displaying data charts, and printed documents with bullet points. Two Japanese professionals are pointing at the screen, engaged in a strategic discussion. The lighting is bright and natural, coming from large windows overlooking a Tokyo cityscape.

By implementing such systems, the IT department will be freed from the routine task of account issuance, allowing them to devote more time to essential activities like IT strategy planning and strengthening security.

FAQ

Q. How should SaaS that do not support SCIM be managed?
A. For tools that do not support SCIM, we either build API integrations using IDaaS workflow features (such as Okta Workflows) or supplement automation via iPaaS. If integration is not feasible, we aim for "semi-automation," where IDaaS handles the automated generation of inventory lists, leaving only the final deletion task to be performed manually.
Q. It seems like coordinating with the HR department for implementation would be difficult.
A. In support settings, we make it easier to gain cooperation by clearly presenting "quantification of security risks" and "the impact of HR input errors on the system." It is important to promote this not just as an IT department issue, but as a company-wide project to strengthen compliance.
Q. Can we prevent permissions from the previous department from remaining after a transfer?
A. Yes, it is possible. By implementing thorough Role-Based Access Control (RBAC) and configuring settings to "revoke" permissions in real-time as group affiliations change, you can maintain the Principle of Least Privilege.

Automate your ID management and strengthen security

We propose strategies to organize complex SaaS account operations and minimize risk.

Talk to us for a free strategy consultation

Popular Topics

Summary

Automating JML (Joiner, Mover, Leaver) management is not just about efficiency; it is an essential security measure for modern cloud-native enterprises. By establishing synchronization with HR data centered on IDaaS provisioning (SCIM integration), you can physically prevent orphaned IDs and excessive permission granting caused by human error. To maximize the use of IT assets and transform into a proactive IT department, start by solidifying the foundation of your ID management.

Published: September 10, 2026 / By: Osamu Yasuda

WRITTEN BY
Osamu Yasuda

Osamu Yasuda

Senior Managing Director & COO

Meets Consulting Inc.

Supported 100+ EC operations & logistics projects; specialist in operations and cost optimization

References

  • [1] RFC 7643: SCIM Core Schema
  • [2] Gartner: Magic Quadrant for Access Management 2024
  • [3] NIST SP 800-207: Zero Trust Architecture
Disclaimer: This article is for informational purposes only and is not intended as a substitute for professional advice. Implementation requires design based on individual requirements.